Rob Hamilton, CEO of Bitcoin self-custody insurance company AnchorWatch, said he was blocked from further analysis after integrating OpenAI's trusted cyber program. "It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open-source models to conduct my research to protect Bitcoin infrastructure," Hamilton wrote.
AI guardrails are impeding the work of legitimate network defenders [1]. Francis Pouliot, founder of Bull Bitcoin, said a Chinese open-source model identified a money-stealing exploit, demonstrated it on regtest, a local Bitcoin testing mode, and helped patch it, according to Bitcoin Magazine.
When he asked the American models he pays for to review the same patch, they refused. "USA AI industry is completely cooked if they don't change this path," Pouliot wrote.
Hamilton reported being blocked again within 19 minutes while using OpenAI's "Daybreak Blue" cyber model to red-team Bitcoin infrastructure, according to Bitcoin Magazine. PortlandHODL, a Bitcoin Core contributor, compared the two options, posting "US-based Frontier AI Model - 'You're absolutely right!' Chinese Open Model - '78 critical vulnerabilities found.' The implications of this are unfathomable."
Alex Thorn, head of firmwide research at Galaxy, said "Americans should not have to rely on Chinese AI to defend themselves, their projects, companies, or clients from cyber-attacks," according to Bitcoin Magazine. In June, the U.S. government placed export controls on Anthropic's Fable 5 and Mythos 5 models [2], and researchers have said the limits are now hindering security work [1].
A firmware flaw in Coldcard hardware wallets was exploited beginning July 30, resulting in the theft of well over $100 million in bitcoin from seeds generated with insufficient entropy, according to Bitcoin Magazine. In response, a volunteer effort known as the Bitcoin Red Team formed, led by open-source developer Calle and Rob Hamilton.
The group conducted large-scale AI-assisted audits of Bitcoin open-source repositories, using models including Kimi K3 as the primary workhorse alongside limited access to Western systems, according to Bitcoin Magazine. By Aug. 8, the team reported scanning 501 projects and producing 7,958 findings – including 1,280 rated high or critical severity, with the majority of compute spending going to Chinese open-weight models.
Chinese models have been gaining ground in the AI race. Clement Delangue, chief executive of Hugging Face, said China is "clearly dominating on open models right now" [3]. Moonshot AI has said that Kimi K3 can rival top American firms [4].
On August 10, the Bitcoin Policy Institute published an open letter signed by more than 70 organizations across the digital-asset ecosystem, according to Bitcoin Magazine. The letter calls on frontier AI labs to establish clear trusted-access programs for qualified open-source and digital-asset defenders. The signatories request early access to cyber-capable models, sufficient compute, secure environments for reviewing code and direct channels with lab security teams.
The letter argues that current restrictions and safety guardrails leave legitimate security researchers without access to the strongest models, forcing them to rely on less capable open-weight alternatives while sophisticated attackers face no such limits. Several AI companies including Hugging Face, Meta, Microsoft, Mistral and Nvidia have urged policymakers not to impose broad "premature restrictions" on open-weight AI models [5].
Calle shared lessons from the red-team period, according to Bitcoin Magazine. He said the low-hanging fruit is largely exhausted and every project should maintain its own permanent AI audit pipeline going forward. He also said the human-only era of open-source security review is over, and advised developers to stop writing security-critical code in C.
"In the past, finding a simple buffer overflow wasn't enough. You'd need a highly skilled hacker to turn the vulnerability into a working end-to-end exploit. Today, that's a single prompt," he wrote.
The shift favors open-source models that can run locally. Chinese open-source models such as DeepSeek have matched or outperformed U.S. systems at lower cost [6]. U.S. technocrats have sought reasons to restrict access to such systems [7].
According to Bitcoin Magazine, Bitcoin is the first major open-source ecosystem to confront this collision between accumulated human code and frontier AI capability, and the rest of the software world is expected to follow.
Developers noted that hosting concerns related to Chinese models can be mitigated because the models are open source and can be run on American-hosted data centers. The Bitcoin Magazine report stated that the trend is likely to threaten the U.S. AI market if restrictions continue. Chinese open-source models have already gained traction among Western corporations [8], and Chinese start-ups continue to compete for market share [9].
The broader software industry is expected to follow Bitcoin as AI-assisted security review becomes standard. Decentralized ledger systems have been described as tools that can increase transparency and reduce corruption [10].